Skip to content

Polish contribution and saved-work recovery across three clients - #22

Draft
oliverdougherC wants to merge 9 commits into
mainfrom
codex/pla-546-547-client-polish-20260923
Draft

oliverdougherC wants to merge 9 commits into
mainfrom
codex/pla-546-547-client-polish-20260923

Conversation

@oliverdougherC

@oliverdougherC oliverdougherC commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Scope

Source implementation for PLA-546 and PLA-547, tracked against the September 22 three-client audit.

  • Add hash-verified, resumable per-clip acquisition and flat, uniquely named staged assets with bound license notices. The checked-in metadata remains published=false until an approved release hosts and verifies all 22 assets.
  • Rebuild submission envelopes for genuinely complete journal groups after a controlled stop, without encoding or re-fetching source media. Add saved-work projection, normal Publish/Resume/Retry controls, due-first replay, host phase exclusion across queue directories, and truthful counters/errors.
  • Validate Windows fields before Running, snapshot active policy, show transfer/storage cost, expose saved campaigns and consent-aware idle retries, and enable Stop/Close cancellation during upload.
  • Add a four-asset manifest gate for coherent source/client/protocol/suite/runtime identities and exact bytes. Show platform eligibility before download and link the current Windows console asset.

Verification

  • Client: 547 passed with the frozen canonical media materialized for the suite tests. A separate clean checkout run had 545 passed and two expected missing-media failures; the task-only media link was removed before committing.
  • Frontend: 78 passed, ESLint and TypeScript checks passed.
  • Focused acquisition: 14 passed; transport cancellation: 11 passed; manifest/release: 11 passed; suite drift check passed.
  • git diff --check passed. No new dependencies.

CI runtime recovery

The original pinned BtbN FFmpeg autobuild tag now returns HTTP 404, causing client/Linux/Windows/preflight jobs to fail before tests. The branch provisions the exact reviewed Linux and Windows FFmpeg/FFprobe bytes from previously published project candidate archives. The archives have pinned SHA-256/size, the extracted binaries are rehashed against the existing runtime lock, and no runtime identity changes. All checks pass on the current rerun: client, frontend, server, migration, stack smoke, clean deployment, audit, preflight, and native Linux/macOS/Windows. Packaged Windows GUI receipt PASSED_AUTOMATED_GUI_CHECKS_VISUAL_REVIEW_PENDING includes prepare/Stop, complete, active Stop and Close with no surviving owned processes; key screenshots were visually reviewed and show the expected local-only and saved-work states. The packaged Windows console seven-clip receipt is PASSED_VIRTUALIZED_WINDOWS_SOFTWARE_ONLY, exit 0, encoder observed, no survivors. Earlier GUI harness failures from the guided mode row and download estimate were corrected in db42acd, fdb7669, 95b1fc4, and fe94dc1.

The four current native candidate artifacts passed assemble_client_release.py against their actual bytes and receipts. They share source 6a5e798c18ae6ba43b8ac21bedeb368434772fce, project 1.3.0-rc.5, client client/0.3.3, protocol 7.1, and frozen suite fingerprint d40bff563dead0e78003af90b2626003bd80afcc12220ab86bc6d4a4b8c83b6e. The source-matched candidate manifest is attached to PLA-546. This is candidate identity verification, not public download or G01 certification.

Release and acceptance gates still open

  • Current public packages do not contain this source. Per-clip assets are staged only, so the public Small flow still requires the existing 1.51 GB pack. Publish/rehash assets and rebuild all Windows GUI/console, macOS arm64 DMG, and Linux x86-64 launcher from one reviewed commit before promotion.
  • PLA-90 G01 still requires actual downloaded-package failure-path acceptance on all three platforms, ordinary-user launch evidence, and manifest-to-download byte comparison. No release, deployment, signing purchase, or production collection is in this PR.
  • HTTP cancellation returns promptly, but a daemon socket worker can linger until its bounded phase timeout after a blocked call. Strict no-orphan acceptance remains open.
  • Legacy journals without a saved clientVersion cannot prove exact client identity across an upgrade when rebuilding a missing envelope. New journals record it and reject mismatches.
  • Near-full storage can leave journal envelopes unadmitted after one Publish saved pass; the UI reports deferred rather than success, and another Publish may be needed. Bounded interleaved staging/drain remains an improvement opportunity.

ofhd added 9 commits September 24, 2026 01:23
The quick clip can be acquired and resumed independently with exact hash and
license verification. A staged flat asset inventory keeps the full-pack
fallback explicit until the per-clip files are published.

Constraint: Protocol 7.1 and frozen canonical bytes cannot change
Constraint: Per-clip assets remain unpublished pending the release gate
Confidence: high
Scope-risk: moderate
Directive: Publish and rehash every flat asset before setting published=true
Tested: 14 acquisition tests; 40 frozen-suite/cancellation checks; suite drift check
Not-tested: Public hosted URLs and native packaged first-launch acquisition
Bound create, authorization and upload phases, and let Stop return promptly
while the durable spool keeps the same local hash for ambiguous outcomes.
Public errors carry safe status and Retry-After information without tokens.

Constraint: Requests transport and protocol 7.1 remain in place
Rejected: Global socket monkey-patching | process-wide side effects
Confidence: medium
Scope-risk: moderate
Directive: A cancelled daemon socket may linger until its phase timeout; do not claim strict no-orphan acceptance
Tested: 22 independent transport-focused tests; 11 artifact cancellation cases
Not-tested: Physical Windows Stop/Close during a stalled upload
Durable journals can rebuild complete unsubmitted groups, while unfinished
groups remain unfinished. A host phase lock excludes measurement and upload
across queue directories. The terminal menu and Windows GUI expose saved
work, safe publication, due retries and truthful pending outcomes.

Constraint: Preserve frozen protocol 7.1 recipes, attempts and receipt IDs
Constraint: Explicit local-only choice and publication consent remain authoritative
Confidence: medium
Scope-risk: broad
Directive: Legacy journals without clientVersion cannot prove upgrade-stable reconstruction; keep that limitation visible
Directive: A storage-limited Publish pass may return deferred with unadmitted envelopes; do not label it published
Tested: 547 full client tests with frozen canonical media; 145 focused recovery/GUI/transport checks; 43 publication/durability checks after final truthfulness fix
Not-tested: Native packaged Windows/macOS/Linux G01 failure-path acceptance or multi-user host locking
One manifest gate now checks all four native asset hashes, wrapper receipts,
source revision, client/protocol/suite identity and runtime fingerprints.
The contribution page places platform eligibility before download and points
Windows CLI users to the verified current console asset.

Constraint: Current rc.5 packages remain published until a new validated candidate exists
Confidence: high
Scope-risk: narrow
Directive: Run the assembler on actual downloaded native assets before promotion; it is not a substitute for G01
Tested: 11 manifest/release tests; 78 frontend tests; ESLint and TypeScript checks
Not-tested: Final candidate native builds, public download byte matches and ordinary-user launch flows
…ears

The reviewed BtbN release tag now returns 404 before client tests or native
builds start. Existing public candidate archives embed the exact locked
Linux and Windows FFmpeg/FFprobe bytes, so CI extracts only those binaries
after verifying archive and runtime-lock hashes. Runtime identity is unchanged.

Constraint: The checked-in FFmpeg runtime lock and protocol identity cannot change
Rejected: Runner FFmpeg packages | required xpsnr/libvmaf capabilities vary
Confidence: high
Scope-risk: moderate
Directive: Do not replace the locked binaries without native model execution and a new reviewed lock
Tested: Local extraction and SHA-256 match for Linux/Windows; anonymous archive HEAD 200; 9 tests; workflow YAML parse
Not-tested: Rerun of all GitHub Actions native jobs and physical packaged-client acceptance
The guided Windows client moved retry and batch controls into Advanced settings, leaving the mode selector in a three-child row. The native harness still required seven children and blocked before it could exercise the packaged GUI. Match the observed three-child mode row with a short label followed by a wider combobox, while retaining owned-window, popup-alignment and unique-row guards.

Constraint: Tk controls have no accessible names in the hosted Windows UIA tree.

Rejected: Hard-coded screen coordinates | cannot establish owned control identity across layouts.

Confidence: medium

Scope-risk: narrow

Directive: Recheck native Win32 control evidence whenever the guided configuration row changes.

Tested: Captured CI Windows screenshot and Win32 tree match the new structural predicate; git diff --check.

Not-tested: Packaged Windows GUI rerun pending CI.
The native selector now recognizes the current three-control guided row, but its pure operator fixtures still supplied the removed retry and batch controls. Refresh the hosted geometry and negative cases so the guard tests exercise the same structural contract before a native build.

Constraint: PowerShell is unavailable on the local macOS host; Windows CI executes the guard suite.

Confidence: medium

Scope-risk: narrow

Tested: Reviewed captured Win32 bounds against fixture; git diff --check.

Not-tested: Windows harness guard rerun pending CI.
The packaged GUI now shows a transfer and storage estimate before source preparation. The Windows harness clicked Start but never answered that dialog, so it timed out waiting for the preparation probe. Verify the owned native dialog, visible cost disclosure and exact Yes/No controls before a bounded Yes click; preserve a path for runs with no transfer prompt. Add operator fixtures for accepted and rejected dialog identities.

Constraint: Native Windows UIA exposes the message box as #32770 with direct Button and Static children.

Rejected: Suppress the estimate prompt in test mode | would skip the contributor decision being certified.

Confidence: medium

Scope-risk: narrow

Directive: Keep consent prompt automation tied to captured native title, text and control IDs.

Tested: Captured Windows screenshot, UIA and Win32 evidence matched the guarded predicate; git diff --check.

Not-tested: Native GUI rerun pending Windows CI.
The native Windows GUI showed the cost dialog, but Tk exposed Stop as Win32-enabled even while its visual state was disabled. The harness treated that flag as proof Start had advanced and never answered the prompt. Prefer the exact owned dialog; only a source preparation probe or owned encode can establish that no prompt was needed.

Constraint: ttk widget state does not reliably map to IsWindowEnabled on hosted Windows.

Rejected: Treat the Stop handle as readiness | the captured modal case disproves that signal.

Confidence: medium

Scope-risk: narrow

Tested: Captured failing receipt showed download-estimate-not-shown with the dialog visible; git diff --check.

Not-tested: Native rerun pending Windows CI.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant